Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
New Atlanta ServletExec未授权访问漏洞
Vulnerability Description
Cisco Collaboration Server使用了New Atlanta提供的ServletExec子组件。 早于5.0的CCS服务程序包含的ServletExec存在访问验证错误,远程攻击者可以利用这个漏洞上传文件并获得管理员权限。 通过ServletExec,攻击者可以上传文件到WEB服务器,并调用它们。攻击者可以提交 http://<ccsservername>/servlet/UploadServlet URL请求来判断漏洞是否存在,如果结果是NullPointerException,那么
CVSS Information
N/A
Vulnerability Type
N/A